United Franchise Group Trust Center
Trust Center
Australian Policy
EU-U.S. Data Privacy Framework Policy
1. Introduction
1.1 United Franchise Group (DBA United Franchise Group), a group of affiliated companies and brands (together “UFG,” “we,” “our,” and “us“), complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF“) and the UK Extension to the EU-U.S. Data Privacy Framework (“UK Extension to the EU-U.S. DPF“), as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Data (as defined below) transferred from the European Union / European Economic Area (“EU/EEA”) and the United Kingdom (and Gibraltar) (“UK”) to the United States.
1.2 UFG has self-certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles, including the Supplemental Principles (collectively, the “DPF Principles“), with regard to the processing of Personal Data received from the EU/EEA in reliance on the EU-U.S. DPF and from the UK in reliance on the UK Extension to the EU-U.S. DPF.
1.3 If there is any conflict between the terms in this Policy and the DPF Principles, the DPF Principles shall govern.
1.4 To learn more about the Data Privacy Framework program, and to view our certification, please visit the Data Privacy Framework List at: https://www.dataprivacyframework.gov/.
2. Definitions
2.1 “Data Subject” means the individual to whom any given Personal Data covered by this Policy refers.
2.2 “Personal Data” means any information relating to an identified or identifiable individual that is within the scope of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) or UK GDPR, received by UFG in the United States from the EU/EEA or UK, and recorded in any form.
2.3 “Sensitive Personal Data” means Personal Data specifying medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information specifying the sex life of the individual.
2.4 “Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure or dissemination, and erasure or destruction.
3. Scope and Responsibility
3.1 This Policy applies to all Personal Data received by UFG in the United States from the EU/EEA in reliance on the EU-U.S. DPF and from the UK (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. This Policy covers non-human resources (“Non-HR“) Personal Data, which includes Personal Data collected through UFG’s websites, platforms, franchise systems, and business operations.
3.2 UFG’s commitments under the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF apply to the following types of Personal Data:
• Contact information (e.g., names, email addresses, phone numbers, mailing addresses)
• Business and professional data (e.g., job titles, company names, franchise-related information)
• Transaction data (e.g., billing information, purchase history, service records)
• Technical and usage information (e.g., IP addresses, browser types, device identifiers, website interaction data)
3.3 Some types of Personal Data may be subject to other privacy-related requirements and policies. For example:
• Some UFG brand websites have their own privacy policies.
• Personal Data regarding and/or received from a client is also subject to any specific agreement with, or notice to, the client, as well as additional applicable laws and professional standards.
• Employee Personal Data is subject to internal human resources policies, including the Employee Data Privacy Notice. HR data is not covered under this Policy.
3.4 All employees of UFG that have access in the U.S. to Personal Data covered by this Policy are responsible for conducting themselves in accordance with this Policy. Adherence by UFG to this Policy may be limited to the extent necessary to comply with a court order or meet public interest, law enforcement, or national security requirements, including where statute or government regulation creates conflicting obligations.
3.5 UFG employees responsible for engaging third parties to which Personal Data covered by this Policy will be transferred are responsible for obtaining appropriate assurances that such third parties have an obligation to conduct themselves in accordance with the DPF Principles, including any applicable contractual assurances.
4. Notice
4.1 UFG informs Data Subjects about the following:
(a) Participation in the DPF. UFG participates in the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Framework. UFG’s participation can be verified on the Data Privacy Framework List maintained by the U.S. Department of Commerce at: https://www.dataprivacyframework.gov/.
(b) Types of Personal Data Collected. UFG collects and processes the following categories of Personal Data: contact information (names, email addresses, phone numbers, mailing addresses); business and professional data (job titles, company names, franchise-related information); transaction data (billing information, purchase history, service records); and technical or usage information (IP addresses, browser types, device identifiers, website interaction data).
(c) Commitment to the DPF Principles. UFG commits to subject all Personal Data received from the EU/EEA in reliance on the EU-U.S. DPF, and from the UK in reliance on the UK Extension to the EU-U.S. DPF, to the DPF Principles.
(d) Purposes of Collection and Use. UFG collects and uses Personal Data for the following purposes:
• Service Delivery & Operations: To provide, operate, and maintain our platforms, systems, and services, and to ensure proper functionality, performance, and support.
• Relationship Management: To manage interactions with customers, franchisees, prospects, partners, and vendors, including onboarding, account administration, communications, and billing.
• Personalization & Experience Improvement: To tailor user experiences, improve service offerings, and enhance engagement based on user activity, preferences, and interactions.
• Analytics & Business Optimization: To analyze system usage, performance trends, and user behavior to improve products, services, and operational efficiency.
• Marketing & Communications: To provide relevant updates, service notifications, and marketing communications, subject to user choices and applicable consent requirements.
• Security & Legal Compliance: To protect the integrity and security of systems, detect and prevent unauthorized activity or fraud, and comply with legal, regulatory, and contractual obligations.
(e) Contact Information. Data Subjects may contact UFG with any inquiries or complaints regarding this Policy or UFG’s data practices at:
United Franchise Group
Attn: Chief Technology Officer / Privacy Contact
2121 Vista Parkway
West Palm Beach, FL 33411, USA
Email: [email protected]
Trust Center: https://trust.unitedfranchisegroup.com
(f) Third Parties Receiving Personal Data. UFG may disclose Personal Data to the following categories of third parties for the purposes described above:
• Service Providers (agents/processors): Technology platform providers, CRM systems, website hosting providers, analytics providers, consent management providers, and other vendors that process Personal Data on UFG’s behalf and under UFG’s instructions.
• Affiliated Entities: UFG’s affiliated companies, brands, and subsidiaries that are part of the United Franchise Group family of brands.
• Business Partners: Franchise partners, master license partners, and co-controllers with whom UFG shares Personal Data pursuant to joint controller agreements or other appropriate arrangements.
• Legal and Regulatory Authorities: Government agencies, courts, or other authorities where disclosure is required by applicable law, regulation, legal process, or enforceable governmental request.
(g) Right of Access. Data Subjects have the right to access their Personal Data held by UFG and to correct, amend, or delete that data as described in Section 9 (Access) below.
(h) Choices and Means for Limiting Use and Disclosure. UFG provides Data Subjects with choices regarding the use and disclosure of their Personal Data as described in Section 5 (Choice) below. Requests should be sent to [email protected].
(i) Independent Recourse Mechanism. UFG has designated ICDR-AAA as its independent recourse mechanism to investigate unresolved complaints free of charge to the individual. Complaints may be submitted through ICDR-AAA’s DPF IRM Service at https://feature.adr.org/dpf_irm.
(j) Enforcement Authority. UFG is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
(k) Binding Arbitration. Under certain conditions, more fully described on the Data Privacy Framework website (https://www.dataprivacyframework.gov), Data Subjects may invoke binding arbitration when other dispute resolution procedures have been exhausted, as set forth in Annex I of the EU-U.S. DPF Principles.
(l) Disclosure to Public Authorities. UFG may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
(m) Liability for Onward Transfers. UFG remains liable under the DPF Principles if its agents process Personal Data covered by this Policy in a manner inconsistent with the Principles, except where UFG is not responsible for the event giving rise to the damage. See Section 6 (Accountability for Onward Transfer) below for further details.
4.2 This notice is provided in clear and conspicuous language when individuals are first asked to provide Personal Data to UFG or as soon thereafter as is practicable, but in any event before UFG uses such information for a purpose other than that for which it was originally collected or processed by the transferring organization or discloses it for the first time to a third party.
5. Choice
5.1 UFG offers Data Subjects the opportunity to choose (i.e., opt out) whether their Personal Data is (i) to be disclosed to a non-agent third party, or (ii) to be used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by the individual. UFG provides Data Subjects with clear, conspicuous, and readily available mechanisms to exercise choice.
5.2 Requests to opt out of such uses or disclosures of Personal Data should be sent to: [email protected].
5.3 It is not necessary to provide choice when disclosure is made to a third party that is acting as an agent to perform task(s) on behalf of and under the instructions of UFG. However, UFG will always enter into a contract with the agent consistent with the DPF Principles.
5.4 For Sensitive Personal Data, UFG will obtain affirmative express consent (i.e., opt in) from Data Subjects before (i) disclosing such information to a third party, or (ii) using it for a purpose other than those for which it was originally collected or subsequently authorized by the individual through the exercise of opt-in choice. In addition, UFG will treat as sensitive any Personal Data received from a third party where the third party identifies and treats it as sensitive.
6. Accountability for Onward Transfer
6.1 Transfers to Controllers. To transfer Personal Data to a third party acting as a controller, UFG will comply with the Notice and Choice Principles. UFG will also enter into a contract with the third-party controller that provides that such data may only be processed for limited and specified purposes consistent with the consent provided by the individual, and that the recipient will provide the same level of protection as the DPF Principles and will notify UFG if it makes a determination that it can no longer meet this obligation. The contract shall provide that when such a determination is made, the third-party controller ceases processing or takes other reasonable and appropriate steps to remediate.
6.2 Transfers to Agents (Processors). To transfer Personal Data to a third party acting as an agent, UFG will: (i) transfer such data only for limited and specified purposes; (ii) ascertain that the agent is obligated to provide at least the same level of privacy protection as is required by the DPF Principles; (iii) take reasonable and appropriate steps to ensure that the agent effectively processes the Personal Data transferred in a manner consistent with UFG’s obligations under the DPF Principles; (iv) require the agent to notify UFG if it makes a determination that it can no longer meet its obligation to provide the same level of protection as is required by the DPF Principles; (v) upon notice, including under (iv), take reasonable and appropriate steps to stop and remediate unauthorized processing; and (vi) provide a summary or a representative copy of the relevant privacy provisions of its contract with that agent to the U.S. Department of Commerce upon request.
6.3 Liability. UFG remains liable under the DPF Principles if an agent processes Personal Data covered by this Policy in a manner inconsistent with the DPF Principles, except where UFG is not responsible for the event giving rise to the damage.
7. Security
7.1 UFG takes reasonable and appropriate measures to protect Personal Data covered by this Policy from loss, misuse, and unauthorized access, disclosure, alteration, and destruction, taking into due account the risks involved in the processing and the nature of the Personal Data. These measures include, but are not limited to, technical safeguards (such as encryption, access controls, and monitoring), organizational measures (such as employee training and security policies), and physical security controls.
8. Data Integrity and Purpose Limitation
8.1 UFG limits the collection of Personal Data covered by this Policy to information that is relevant for the purposes of processing. UFG does not process such Personal Data in a way that is incompatible with the purposes for which it has been collected or subsequently authorized by the Data Subject.
8.2 UFG takes reasonable steps to ensure that Personal Data is reliable for its intended use, accurate, complete, and current. UFG retains Personal Data in identifiable form only for as long as it serves a purpose of processing within the meaning of this Principle, including UFG’s obligations to comply with professional standards, business purposes, and applicable legal and regulatory requirements. UFG adheres to the DPF Principles for as long as it retains such Personal Data.
9. Access
9.1 Data Subjects have the right to access Personal Data about them that UFG holds and to correct, amend, or delete that information where it is inaccurate or has been processed in violation of the DPF Principles, except where the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy in the case in question, or where the rights of persons other than the individual would be violated.
9.2 Requests for access, correction, amendment, or deletion should be sent to: [email protected]. UFG will respond to such requests within a reasonable timeframe.
10. Recourse, Enforcement, and Liability
10.1 Enforcement. UFG’s participation in the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Framework is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
10.2 Complaints. In compliance with the DPF Principles, UFG commits to resolve complaints about your privacy and our collection or use of your Personal Data. Data Subjects with inquiries or complaints regarding this Policy should first contact UFG at: [email protected]. UFG will respond to complaints within 45 days of receipt.
10.3 Independent Recourse Mechanism. UFG has further committed to refer unresolved privacy complaints under the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF to ICDR-AAA, an independent dispute resolution mechanism. This service is provided at no cost to the individual. To submit a complaint to ICDR-AAA, please visit https://feature.adr.org/dpf_irm.
10.4 Binding Arbitration. Under certain conditions, as more fully described on the Data Privacy Framework website at https://www.dataprivacyframework.gov, and as set forth in Annex I of the EU-U.S. DPF Principles, a Data Subject may invoke binding arbitration when other dispute resolution procedures have been exhausted. The binding arbitration option is available for residual claims not resolved by any other means.
10.5 Verification. UFG will verify its compliance with the DPF Principles through a self-assessment process and will remedy any issues arising out of failure to comply with the DPF Principles. UFG will affirm its compliance to the U.S. Department of Commerce on an annual basis. UFG acknowledges that its failure to provide an annual re-certification to the U.S. Department of Commerce will remove it from the Data Privacy Framework List.
10.6 Continuing Obligations. If UFG ceases to participate in the DPF program, it will either continue to apply the DPF Principles to the Personal Data received under the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and affirm to the U.S. Department of Commerce on an annual basis its commitment to do so, provide “adequate” protection for the information by another authorized means, or return or delete the information.
11. Disclosure to Public Authorities
11.1 UFG may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. UFG’s adherence to this Policy may be limited to the extent necessary to comply with a court order or meet public interest, law enforcement, or national security requirements, including where statute or government regulation creates conflicting obligations, provided that, in exercising any such authorization, UFG can demonstrate that its non-compliance with the DPF Principles is limited to the extent necessary to meet the overriding legitimate interests furthered by such authorization.
12. Amendments
12.1 This Policy may be amended from time to time consistent with the requirements of the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.
12.2 UFG will provide appropriate notice regarding any material amendments to this Policy.
12.3 Any material changes to this Policy will be posted on UFG’s Trust Center at https://trust.unitedfranchisegroup.com.
13. Data Protection / Privacy Contact
13.1 Our privacy contact’s details are:
United Franchise Group
Attn: Chief Technology Officer / Privacy Contact
2121 Vista Parkway
West Palm Beach, FL 33411, USA
Email: [email protected]
Phone: (561) 868-1497
Trust Center: https://trust.unitedfranchisegroup.com
13.2 For complaints that cannot be resolved directly with UFG, please contact our independent recourse mechanism:
ICDR-AAA
DPF IRM Service: https://feature.adr.org/dpf_irm
General inquiries: 888-855-9575
International Centre for Dispute Resolution / American Arbitration Association











